Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,394 CVEs tagged with CWE-522217 Critical, 485 High, 645 Medium, 45 Low, 2 Unrated.

CVE-2024-51240

Published Nov 5, 2024

An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc p…

CVSS 8.0 · High

CVE-2024-34885

Published Nov 4, 2024

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34887

Published Nov 4, 2024

Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34883

Published Nov 4, 2024

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET reque…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34882

Published Nov 4, 2024

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server vi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50310

Published Oct 23, 2024

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized inte…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43812

Published Oct 22, 2024

Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthenticated attacker with access to /etc/passwd to read the pass…

CVSS 8.6 · High

CVE-2024-44000

Published Oct 20, 2024

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-7755

Published Oct 17, 2024

The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network can sniff the traffic and decode the credentials.

CVSS 7.1 · High

CVE-2024-49396

Published Oct 17, 2024

The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.

CVSS 8.7 · High

CVE-2024-47161

Published Oct 8, 2024

In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47805

Published Oct 2, 2024

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when a…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-45744

Published Sep 27, 2024

TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt e…

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-31899

Published Sep 26, 2024

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9014

Published Sep 23, 2024

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret,…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8986

Published Sep 19, 2024

The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git rem…

CVSS 9.1 · Critical

CVE-2024-8777

Published Sep 16, 2024

OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is en…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28981

Published Sep 12, 2024

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.

CVSS 8.5 · High
Showing 301-325 of 1,394 CVEsPage 13 of 56